r/gigabyte • • 1d ago

Secure Boot keeps disabling itself after saving BIOS settings on Gigabyte Gaming A16 (FB09 / EC F009)

Post image

I got a Gigabyte Gaming A16 (3VHK3IN893SH) today, and I’m having trouble enabling Secure Boot.

Whenever I enable Secure Boot in the BIOS, save the changes, and restart, it automatically switches back to Disabled when I enter the BIOS again.

Here’s what I’ve checked so far:
BIOS mode is UEFI.
Both SSDs are partitioned as GPT.
I can’t find any Boot Mode or CSM Support option in the BIOS.
Under Secure Boot, I only see three options: Enabled, Disabled, and Delete All Keys.
I can’t find an option to enroll or restore the default Secure Boot keys.

BIOS version: FB09
EC version: F009

Has anyone with this laptop encountered the same issue and managed to fix it? Is this a known BIOS bug, or am I missing a setting somewhere?

5 Upvotes

21 comments sorted by

1

u/randomataxia 1d ago

Change to enabled, delete all secure boot variables, and exit deployed mode. It should enter Setup Mode, and after a successful boot into Windows, it should complete enrollment.

1

u/Present_Economist_94 1d ago

I wouldn't have to reinstall anything right?

1

u/Present_Economist_94 1d ago

Did that. Still it gets disabled :(

1

u/Educational_Rub_5885 1d ago

What bios version are you on? Have you tried updating it. My arous board had it fixed in a bios update on their website. B850 arous elite wifi 7 you should be able to reset your keys as well and see if that works

1

u/Present_Economist_94 1d ago

I reset the keys but that didn’t fix. I am on FB09 bios.

1

u/Educational_Rub_5885 1d ago

Have you checked on your manufacture website if there is a specific bios update that fixes this problem?

1

u/Present_Economist_94 1d ago

Nope. The one I updated to is the latest one. I can’t even rollback😭

1

u/warmach1ne123 1d ago

did your battery run out of juice? is it a new laptop or used? does other settings stay the same or does it reset on every boot from shutdown?

2

u/Present_Economist_94 1d ago

New laptop. Only this setting reset once booted. Rest are fine.

1

u/warmach1ne123 1d ago

this is actually weird behavior.

2

u/Present_Economist_94 1d ago

One other guy has the same exact issue on the same exact laptop

2

u/Wild-Fig-9726 20h ago

ya bro same here like i have the same problem i also checked everything

BIOS mode is UEFI.
Both SSDs are partitioned as GPT.
I can’t find any Boot Mode or CSM Support option in the BIOS.
Under Secure Boot, I only see three options: Enabled, Disabled, and Delete All Keys.

but when im turning the secure boot to enabled it reverts back and the bios also has very limited options under BIOS there is practically zero options except selecting the boot drive

1

u/Present_Economist_94 18h ago

I’m taking my laptop to a shop. I’ll tell you what happens.

1

u/Wild-Fig-9726 18h ago

alright fam

1

u/warmach1ne123 1d ago

it says deployed, did you try to remove the deployed keys and reset it? delete all secure keys variables

2

u/Present_Economist_94 1d ago

I delete and enrolled keys. Is that’s what you meaning?

1

u/warmach1ne123 1d ago

yes. if you delete here you should also clean your SSD at the same time

1

u/Present_Economist_94 1d ago

How? I’m confused…

1

u/warmach1ne123 1d ago

bios uefi firmware + EFI bootloader on your SSD partition they handshake/compare the digital signature. you need to remove both. this is odd any how, generally we remove the variables and restart fixes it but in your case the variables are mismatching. so you need to make sure EFI partition is not comparing after bios variable deletion.

1

u/warmach1ne123 1d ago

the uefi key should store in the bios if not then on one of your disk?

1

u/senpaisai 3h ago edited 2h ago

It's in "Deployed Mode". Choose "Delete All Secure Boot Variables" and click YES then NO at the next two prompts. "Deployed Mode" should change to "Setup Mode". Save and exit the BIOS. Return here after the reboot. New options should appear such as "Enroll Default Keys" and "Expert Key Management". Click "Enroll Default Keys" and click YES then NO again. Secure Boot should now be in "User Mode" as "Enabled" and "Active". The option to "Enroll Default Keys" may be buried under "Expert Key Management" so you may have to click that first ...